CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September
Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Versa Director security issue to its list of known exploited vulnerabilities (KEVs).
A file upload problem affecting the "Change Favicon" feature is the source of the medium-severity vulnerability, identified as CVE-2024-39717 (CVSS score: 6.6). This exploit could enable a threat actor to submit a malicious file by disguising it as a seemingly innocent PNG image file.
According to a CISA alert, administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin access can alter the user interface of the Versa Director GUI through an unlimited upload of files with a hazardous type vulnerability read more about CISA Urges Federal Agencies to Patch Versa D...

